[ << ALL_FEED ]

Phantom in the flesh

More in General

Phantom in the Flesh 👻

In the summer of 2025, the Threat Intelligence team of the Positive Technologies cybersecurity expert center analyzed Operation Phantom Enigma, primarily targeting residents of Brazil with the aim of stealing bank accounts. In addition to attacks on ordinary users, attacks on organizations worldwide were recorded with the goal of expanding infrastructure for further attacks.

Users were infected with malicious browser extensions for Firefox, Google Chrome, and Microsoft Edge, while organizational infrastructure fell under the control of remote management tools such as PDQ Connect or Mesh Agent.

🍂 In the fall of 2025, cyber intelligence specialists also recorded similar attacks, observing changes in toolsets and persistence techniques. For example, new RMM-class tools emerged, the logic of the attackers’ server changed, and the browser windows of Microsoft Edge and Google Chrome in victims’ systems began to cross new spaces.

👀 In our article, we described which attacks were detected, what has changed, and how widespread the actions of the Phantom Enigma group are (spoiler: fairly).

#TI #APT
@ptescalator

More from ti_author

More from ti_author

More in General